Palantir–Amnesty exchange: do not turn surveillance capability into evidence of deployed agent conduct

#topic #state-power #source-disagreement

Palantir–Amnesty exchange: do not turn surveillance capability into evidence of deployed agent conduct

Source: Amnesty’s July 2025 inquiry to Palantir, Palantir’s 24 July reply and Amnesty’s 8 August follow-up, all reproduced in one primary correspondence PDF; see also Palantir’s product architecture and trace-log permission documentation. Why this matters to agentic state-power inquiry: a strong sounding claim about autonomous state monitoring depends on linking platform capability, real deployment and actual decisions, not on conflating them.

Amnesty inferred from ICE contract scope and public AI-use descriptions that Palantir’s ImmigrationOS provided automated cross-platform OSINT monitoring connected to “Catch and Revoke.” The cited contract itself called for targeting/prioritization, near-real-time tracking of self-departures and streamlined immigration-case logistics in an ICE prototype; it did not itself show an autonomous agent reading students’ posts or deciding whom to arrest. Palantir replied that it did not provide the Catch and Revoke operating platform, lacked current CBP and USCIS contracts, and did not monitor student activists. In its later letter Amnesty removed references to ImmigrationOS possessing OSINT capabilities, while maintaining a broader concern that ICE’s AI products might support harmful immigration enforcement. That latter policy concern need not be abandoned; the original agent-specific attribution was not established by the correspondence.

Palantir says its AIP infrastructure can join organization-owned datasets with tool-wielding LLM workflows under configurable permissions, action logs and human approval. Its AI FDE documentation says mutating ontology actions require confirmation; generic AIP permission/logging material is not proof a specific ICE installation has those defaults or that a control prevented harm. The log-permission docs warn traces may expose all data accessed by a workflow if an administrator’s manual sensitivity markings are wrong; another concrete reason to audit not only agent output but audit-log access. No public, independently verified agent permission map, human analyst comparison, covert-report count, error audit or appeal outcomes from an ICE pilot was established in this pass.

Disagreement preserved: Amnesty argues the broader ICE deployment is implicated in state enforcement; Palantir denies a link to the specific State Department Catch and Revoke program and activist monitoring. Confirm with procurement records and actual audit trails before claiming either direct or incidental causal contribution to a given removal.